SSH Commands / Tricks
blog.urfix.com
blog.urfix.com
See: An almost invisible ssh connection
ssh -T user@host /bin/bash -i
This connects you to a box with no TTY allocation. If someone types 'w', they will not see your connection.ps aux | grep sshd.*notty
sudo lsof -i :22
you can then reverse what people are doing based on the pids lsof gives you.[edit: using ps ax | grep sshd also works but you can't see where they are connecting from. [+1 daten]]
ssh -t user@host screen -ln
since you get a full fledged shell with job control and everything
Text only cache: http://webcache.googleusercontent.com/search?q=cache:http://...
sshuttle is a transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin access. Works with Linux and MacOS.
Avery Pennarun is a Hero :)
You can do this
# sshuttle -v -r user@host:443 10.0.0.0/8 # ssh user@10.0.0.138
Connections to 10.0.0.0/8 goes through ssh automatically.
Nice piece of code - tons of interesting possibilities there.
For security he might want to relocate the admin login URL as well since he still has it set to /wp-admin/ .
http://blog.urfix.com/wp-config.php
I can see their config in plain text.
~.
to terminate a stalled session. Supported escape sequences:
~. - terminate connection (and any multiplexed sessions)
~B - send a BREAK to the remote system
~C - open a command line
~R - Request rekey (SSH protocol 2 only)
~^Z - suspend ssh
~# - list forwarded connections
~& - background ssh (when waiting for connections to terminate)
~? - this message
~~ - send the escape character by typing it twice
(Note that escapes are only recognized immediately after newline.)
If you open the command line (~C), another '?' shows its available commands: ssh> ?
Commands:
-L[bind_address:]port:host:hostport Request local forward
-R[bind_address:]port:host:hostport Request remote forward
-KR[bind_address:]port Cancel remote forwardPrevious ssh fu posts:
http://news.ycombinator.com/item?id=1536126
ssh user@host cat /path/to/music-collection | mplayer
21) Have an ssh session open forever
autossh -M50000 -t server.example.com ‘screen -raAd mysession’
Open a ssh session opened forever, great on laptops losing Internet connectivity when switching WIFI spots.
24) Transfer SSH public key to another machine in one step
ssh-keygen; ssh-copy-id user@host; ssh user@host
This command sequence allows simple setup of (gasp!) password-less SSH logins. Be careful, as if you already have an SSH keypair in your ~/.ssh directory on the local machine, there is a possibility ssh-keygen may overwrite them. ssh-copy-id copies the public key to the remote host and appends it to the remote account’s ~/.ssh/authorized_keys file. When trying ssh, if you used no passphrase for your key, the remote shell appears soon after invoking ssh user@host.
25) Copy stdin to your X11 buffer
ssh user@host cat /path/to/some/file | xclip
ssh user@host cat /path/to/some/file | pbcopy
ServerAliveInterval 10
The client sends a keepalive packet every 10 seconds.Except that your mysql password is now in your history?
Here's a pretty good expression of the main complaint I've heard about MacPorts:
> The system [homebrew] is much better than MacPorts, the idea is that for example, Mac OS X comes with python installed. Brew will try to use the default python installation instead of trying to make it's own in /usr/opt/whatever ... so, homebrew premise, is to respect the Mac OS X installed packages and use them to it's favor + respecting the Mac OS X structure ( don't re create a whole new structure like fink and mac ports )
- http://stackoverflow.com/questions/189912/what-package-manag...
An added bonus is that things tend to install way faster because it's not compiling all of this stuff that OS X came with.
It lets you temporarily give a behind-the-firewall web server a public, port 80 URL.
ssh -D9999 user@remotehost.com
And now I have a local SOCKS proxy running. I just have to change the proxy configuration in my browser using SOCKS4a at localhost:9999 and I can surf as if I were on remotehost ssh -ND 9999
it doesn't open a shell.This may stop you from accidentally shutting down your tunnel thinking it's just another ssh session.
Does anyone know: Is it recommended to mount a directory via sshfs? My idea: Mount whole server filesystems into /mnt/servers/<server_ip> ... and then conveniently work with it using desktop tools.
Can it be done? What are the downsides to that?
On OSX with MacFuse and SSHFS, I've done plenty of remote work before on LAN servers and "internet" servers. It definitely works, but is slow. But for being able to open up a "local" file in Vim/text editor and then save it, the only time you are hitting the network is during the save and that can be slow.
Transmit 4 integrated this functionality into their FTP client, auto-mounting of SSH connections, but it definitely seems more crashy than MacFuse to me.
I've been using vim for a decade or more. I guess it's a salutary lesson for experienced users. I should read the Changelog more carefully when upgrading.
NFS, however, doesn't encrypt, while sshfs does, so if you don't care about encryption, NFS will be a lot faster.
The proper way to do what you want is to install those desktop tools on the remote machine, and then use ssh X forwarding (ForwardX11 and ForwardX11Trusted in the manual, also -X and -Y) to have those programs run on the remote machine, but display their GUIs on your local desktop. This way you get the nice graphical interfaces while still doing all the hard work on the remote machine, without copying tons of data back and forth.
"Will allow you to mount a folder security over a network."
I guess the author meant instead:
"Will allow you to mount a folder securely over a network."
Rob Pike
http://interviews.slashdot.org/article.pl?sid=04/10/18/11532...
Very useful.